PT-2026-51446 · Unknown · Openkm Community Edition
CVE-2026-46495
·
Published
2026-06-22
·
Updated
2026-06-25
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenDJ Community Edition versions prior to 5.1.1
Description
A Deserialization of Untrusted Data issue in the JMX RMI connector allows an unauthenticated remote attacker to deserialize arbitrary Java objects on the server. The issue occurs because the platform processes attacker-controlled bytes before authentication. This affects systems where the JMX Connection Handler is enabled, which is often done for monitoring integrations. Successful exploitation leads to Remote Code Execution (RCE), the severity of which depends on the Java version and runtime classpath.
Recommendations
Update to version 5.1.1.
As a temporary mitigation, disable the JMX Connection Handler if it is not required for monitoring.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openkm Community Edition